# IP Intelligence Briefing: 185.8.106.168
## Executive Summary
IP address 185.8.106.168 is classified as Low Risk with an overall risk score of 25. The address belongs to Cherry Servers NOC (AS204770) and is registered under the CHERRYSERVERS-DEDICATED network block. No active threat indicators were identified in the current profile, though historical data shows intermittent DNSBL listings and geolocation inconsistencies.
## Technical Profile
- Owner: Cherry Servers NOC (AS204770)
- Network: CHERRYSERVERS-DEDICATED (185.8.106.128/25)
- Geolocation: Primary attribution to New York, US (US-NY). Historical signals show conflicting data including Chicago, IL and Lithuania (LT).
- DNS Resolution: ip-185-8-106-168.003.ptr.cherryservers.net
- Services: No open ports detected; classified as Firewalled/No Services
- DNSBL Status: Listed on 1 of 8 DNSBL lists with high severity rating observed in history
## Threat Indicators
Current profile shows no active threat indicators:
- No known attacker flags
- Not a Tor exit node
- No spam source designation
- No associated threat campaigns
- No known malicious activity in current threat feeds
## Historical Observations
Sixteen historical signals reveal notable inconsistencies:
- One signal (07-28-2026) associated ASN AS16125 with Lithuania coordinates (56N, 24E)
- Another signal attributed to Chicago, Illinois, US
- DNSBL listings detected with maximum severity rating of "high"
- Operator score of 0.2609 labeled as "Basic"
- No persistent malicious behavior observed over time
## Network Context
The /24 subnet (185.8.106.168/24) contains 8 sibling IPs with the following risk distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 8
Neighbor IP risk scores range from 0 to 25. Notable neighbors include:
- 185.8.106.92, 185.8.106.94, 185.8.106.145, 185.8.106.150, 185.8.106.170, 185.8.106.172, 185.8.106.219
Subnet abuse density is 0, indicating low neighborhood-level threat concentration.
## Recommended Actions
Based on the current risk profile and historical data, the following actions are recommended:
1. Monitor DNSBL Listings: Investigate the 1 of 8 DNSBL listings and assess whether listing removal is required
2. Geolocation Validation: Monitor for continued geolocation inconsistencies between New York, Chicago, and Lithuania
3. Traffic Baseline: Establish baseline traffic patterns for this IP to identify anomalies
4. Subnet Monitoring: Continue monitoring the 185.8.106.0/24 subnet for any risk escalation
## Conclusion
IP 185.8.106.168 presents a low-risk profile with Cherry Servers as the hosting provider. While current threat indicators are absent, historical DNSBL listings and geolocation inconsistencies warrant continued monitoring. The subnet shows healthy abuse density levels with no high-risk neighbors detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cherry Servers NOC |
| ASN | AS204770 |
| Network Name | CHERRYSERVERS-DEDICATED |
| CIDR Block | 185.8.106.128/25 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | ip-185-8-106-168.003.ptr.cherryservers.net |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | ip-185-8-106-168.003.ptr.cherryservers.net |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 87 days |
🛡️ Public Network Snapshot
| Origin ASN | AS204770 |
| Network Prefix | 185.8.106.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 04:31:29 UTC |
| Last Seen | 2026-09-02 21:04:21 UTC |
| Profile Built | 2026-09-02 21:07:11 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.8.106.168
Who owns the IP address 185.8.106.168?
185.8.106.168 is registered to Cherry Servers NOC. The address falls within the 185.8.106.128/25 network block. Registration is held at RIPE.
Where is 185.8.106.168 located?
Geolocation data places 185.8.106.168 in Chicago, Illinois, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.8.106.168 malicious or safe?
185.8.106.168 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 185.8.106.168?
The reverse DNS (PTR) record for 185.8.106.168 is ip-185-8-106-168.003.ptr.cherryservers.net. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 185.8.106.168?
Responsive ports observed on 185.8.106.168 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.